D-TRUST non-BR-compliant certificate issuance and delayed revocation/remediation
This case concerns D-TRUST certificates that Mozilla identified as not compliant with Baseline Requirements, including a certificate with a dNSName containing '/' and certificates with short or sequential-looking serial numbers. Mozilla opened the bug after problems were reported in mozilla.dev.security.policy and asked D-TRUST to stop issuance, identify affected certificates, explain the cause, and provide a remediation and revocation plan. D-TRUST said it had stopped the problematic issuance, revoked the dNSName certificate, and later worked through revocation of the short-serial-number certificates in phases. The thread also records D-TRUST’s explanations for the issuance issues, including a CSR validator bug, UI/usability issues, and a delayed serial-number migration across platforms. For the short-serial-number issue, D-TRUST eventually reported that all affected certificates were revoked by 2018-07-16, and Mozilla later said the issue was resolved. For the dNSName issue, D-TRUST reported the certificate was revoked and a replacement BR-compliant certificate was issued.
- D-TRUST stopped issuing certificates with the dNSName '/' problem
- The dNSName-containing certificate was revoked
- D-TRUST reported a final incident report and revocation plan for the affected certificates
- D-TRUST reported that all short-serial-number certificates were revoked
- Mozilla said the issue was resolved
- Mozilla representative — Mozilla opened the bug and requested details on awareness, issuance stoppage, affected certificates, root cause, remediation steps, and revocation timing.
- D-Trust — D-TRUST said it learned of the CN/SAN issue from mozilla.dev.security.policy and the serial-number issue from an internal audit, and it described initial remediation steps and timelines.
- D-Trust — D-TRUST explained the GUI usability issue and CSR validator bug, and said it had extended software testing and vendor/customer change processes.
- D-Trust — D-TRUST provided a revised timeline, said the dNSName certificate was revoked, and said it would finalize revocation of affected serial-number certificates by 2017-09-15.
- Bdr representative — D-TRUST filed final reports for both incidents, stating the dNSName certificate was revoked and that the short-serial-number issue involved phased replacement and revocation.
- Bdr representative — D-TRUST reported that all certificates with short serial numbers were revoked in three phases.
- Bdr representative — D-TRUST said the remaining revocations were completed by 2018-07-16, that 150 certificates were published to CT logs, and that 111 had no customer approval for publication.
- Fastly representative — Mozilla stated that the response had been informative and that the issue was resolved.